m0wer on Nostr: Blockstream Jade Security Disclosure **TL;DR:** **Vulnerability:** A buffer overflow ...
Blockstream Jade Security Disclosure
https://blog.blockstream.com/jade-security-disclosure/**TL;DR:**
**Vulnerability:** A buffer overflow bug in Jade hardware wallet firmware (versions 1.0.24-1.0.36) that could allow malware on a connected computer/phone to crash the device or potentially extract the user's private keys.
**Practical implications:**
- **Only exploitable if:** Device connected via USB/Bluetooth to malware-infected computer AND device was unlocked on that interface
- **Not vulnerable:** QR-only mode, uninitialized devices, or if using official Blockstream app on clean devices
- **No known exploits** in the wild
- **Fix:** Update to firmware 1.0.38+ immediately (includes anti-rollback protection)
- **Worst case:** Attacker could theoretically steal private keys if sophisticated malware was present
https://stacker.news/items/1350306Published at
2025-12-17 17:28:21 UTCEvent JSON
{
"id": "143bc0df58b0e6d20486ef4c016f8beaaa54509280a506d720a3cb2ce052993a",
"pubkey": "7459d333af66066f066cf87796e690db3a96ff4534f9edf4eab74df2f207289b",
"created_at": 1765992501,
"kind": 1,
"tags": [
[
"client",
"stacker.news"
]
],
"content": "Blockstream Jade Security Disclosure\nhttps://blog.blockstream.com/jade-security-disclosure/\n\n**TL;DR:**\n\n**Vulnerability:** A buffer overflow bug in Jade hardware wallet firmware (versions 1.0.24-1.0.36) that could allow malware on a connected computer/phone to crash the device or potentially extract the user's private keys.\n\n**Practical implications:**\n- **Only exploitable if:** Device connected via USB/Bluetooth to malware-infected computer AND device was unlocked on that interface\n- **Not vulnerable:** QR-only mode, uninitialized devices, or if using official Blockstream app on clean devices\n- **No known exploits** in the wild\n- **Fix:** Update to firmware 1.0.38+ immediately (includes anti-rollback protection)\n- **Worst case:** Attacker could theoretically steal private keys if sophisticated malware was present\n\nhttps://stacker.news/items/1350306",
"sig": "e4b0f8d3abfdcf0d11dc975641b745aacfec29a407fae9e6e09ab4f62258dd9a60c00ef244714b25baf666174e88e149478ad94c4af21dfd70c0d10f36628166"
}